CVE-2014-1552

Firefox < 30.0 and Thunderbird < 24.7 - Sandbox Bypass via IFRAME Redirect

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60628
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59760
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=985135
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030620
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030619
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Details

CWE
CWE-264
Status published
Products (11)
mozilla/firefox < 30.0
mozilla/thunderbird 24.0
mozilla/thunderbird 24.0.1
mozilla/thunderbird 24.1
mozilla/thunderbird 24.1.1
mozilla/thunderbird 24.2
mozilla/thunderbird 24.3
mozilla/thunderbird 24.4
mozilla/thunderbird 24.5
mozilla/thunderbird 24.6
... and 1 more
Published Jul 23, 2014
Tracked Since Feb 18, 2026